Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Ransom Notes:

IOC

Your systems were accessed and encrypted by Cactus.
Do not interrupt the encryption process, don't stop or reboot your machines.
Otherwise the data may be corrupted and unrecoverable.
The best you can do is wait until encryption is finished to keep your files safe
.
Besides, we have downloaded a huge pack of confidential information from your sy
stems.
Your data will be sold or published in our blog https:\cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid.onion in case of non-payment
To recover your files and prevent disclosure of your sensitive data contact us via email: cactus@mexicomail.com
Your unique ID: [snip]
Backup contacts: http://sonarmsng5vzwqezlvtu2iiwwdn3dxkhotftikhowpfjuzg7p3ca5eid.onion/contact/Cactus_Support
TOX (https://tox.chat/):
7367B422CD7498D5F2AAF33F58F67A332F8520CF0279A5FBB4611E0121AE421AE1D49ACEABB2

Indicators of Compromise
Type IOC
email cactus@mexicomail.com
onion url http://cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid.onion
onion url http://sonarmsng5vzwqezlvtu2iiwwdn3dxkhotftikhowpfjuzg7p3ca5eid.onion/contact/Cactus_Support
tox id 7367B422CD7498D5F2AAF33F58F67A332F8520CF0279A5FBB4611E0121AE421AE1D49ACEABB2